Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f5e22fb411b4ed34f57fceb2a5be99d294887440389a1d5c
Public Swagger UI/API detected at path: /api/swagger.json - sample paths:
DELETE /api/auth/logout
GET /api/encaminhamento/buscar/{id}
GET /api/endereco/buscar?endereco={endereco}
GET /api/endereco/converte?endereco={endereco}
GET /api/paciente/por-cpf/{cpf}
GET /api/usuario/me
PATCH /api/auth/refresh
POST /api/arquivo/adicionar
POST /api/auth/login
POST /api/auth/login-sis
POST /api/encaminhamento/adicionar
POST /api/encaminhamento/atualizar/{id}
POST /api/encaminhamento/busca-avancada
POST /api/encaminhamento/envia-arquivos/{id}
POST /api/encaminhamento/remove-arquivos/{id}
POST /api/escala/busca
POST /api/especialidade/busca-avancada
POST /api/paciente/atualiza-foto/{id}
POST /api/paciente/atualizar/{id}
POST /api/paciente/cadastrar
POST /api/profissional/busca-avancada
POST /api/unidade/busca-avancada
PUT /api/auth/change-password
PUT /api/auth/reset-password
Severity: info
Fingerprint: 5733ddf49ff49cd1f5e22fb411b4ed34f57fceb2a5be99d29488744044ca6a48
Public Swagger UI/API detected at path: /api/swagger.json - sample paths:
DELETE /api/auth/logout
GET /api/encaminhamento/buscar/{id}
GET /api/endereco/buscar?endereco={endereco}
GET /api/endereco/converte?endereco={endereco}
GET /api/paciente/por-cpf/{cpf}
GET /api/usuario/me
PATCH /api/auth/refresh
POST /api/auth/login
POST /api/auth/login-sis
POST /api/encaminhamento/adicionar
POST /api/encaminhamento/atualizar/{id}
POST /api/encaminhamento/busca-avancada
POST /api/encaminhamento/envia-arquivos/{id}
POST /api/encaminhamento/remove-arquivos/{id}
POST /api/escala/busca
POST /api/especialidade/busca-avancada
POST /api/paciente/atualiza-foto/{id}
POST /api/paciente/atualizar/{id}
POST /api/paciente/cadastrar
POST /api/profissional/busca-avancada
POST /api/unidade/busca-avancada
PUT /api/auth/change-password
PUT /api/auth/reset-password
Severity: info
Fingerprint: 5733ddf49ff49cd1f5e22fb411b4ed34f57fceb2a5be99d2948874405e099ecf
Public Swagger UI/API detected at path: /api/swagger.json - sample paths:
DELETE /api/auth/logout
GET /api/encaminhamento/buscar/{id}
GET /api/endereco/buscar?endereco={endereco}
GET /api/endereco/converte?endereco={endereco}
GET /api/paciente/por-cpf/{cpf}
GET /api/usuario/me
PATCH /api/auth/refresh
POST /api/auth/login
POST /api/auth/login-sis
POST /api/encaminhamento/adicionar
POST /api/encaminhamento/atualizar/{id}
POST /api/encaminhamento/busca-avancada
POST /api/encaminhamento/envia-arquivos/{id}
POST /api/encaminhamento/remove-arquivos/{id}
POST /api/escala/busca
POST /api/especialidade/busca-avancada
POST /api/paciente/atualiza-foto/{id}
POST /api/paciente/atualizar/{id}
POST /api/paciente/cadastrar
PUT /api/auth/change-password
PUT /api/auth/reset-password